PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47130 pdovhomilja CVE debrief

A high-severity vulnerability exists in NextCRM, an open-source customer relationship management software. The issue, identified as CVE-2026-47130, affects versions prior to 0.12.0 and is classified as a Broken Object Level Authorization (BOLA/IDOR) vulnerability. This vulnerability allows any authenticated user, even those with a standard 'member' role, to arbitrarily modify sensitive CRM contacts and targets belonging to other users or organizations, potentially leading to cross-tenant data tampering. Evidence basis is limited to CVE and NVD information.

Vendor
pdovhomilja
Product
nextcrm-app
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-20
Original CVE updated
2026-07-22
Advisory published
2026-07-20
Advisory updated
2026-07-22

Who should care

Organizations using NextCRM versions prior to 0.12.0 should prioritize upgrading to the latest version to mitigate this vulnerability. Additionally, users with access to CRM contacts and targets should be cautious of potential unauthorized modifications. Affected operator, platform, vulnerability-management, and security-team impact should be reviewed.

Technical summary

The vulnerability exists in the CRM contact and target update endpoints of NextCRM. The application fails to verify if the authenticated user has ownership of the specific resource being modified, allowing for arbitrary modifications by any authenticated user. This issue is addressed in version 0.12.0 of NextCRM. Affected product deployments should be reviewed for exposure. The issue allows cross-tenant data tampering, impacting organizations using NextCRM versions prior to 0.12.0. Evidence basis is limited to CVE and NVD information, and defenders should verify affected scope and vendor guidance.

Defensive priority

High

Recommended defensive actions

  • Upgrade NextCRM to version 0.12.0 or later
  • Review and restrict access to CRM contacts and targets
  • Monitor for suspicious activity in CRM systems
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record was published on 2026-07-20T21:16:47.917Z and was last modified on 2026-07-22T20:50:36.493Z. The NVD entry is currently Deferred. Evidence is limited to CVE and NVD information. Defenders should verify affected scope and vendor guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-47130 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-47130

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-47130 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47130

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.